https://seclists.org/oss-sec/2026/q3/651: Vulnerabilities fixed in libxml2-2.15.4
Published Sep 4, 2026
·Updated
Affected Software
1 affected component
libxml2=2.15.4
The release notes identify fixes in xmlregexp, dict.c, uri.c, valid.c, xpointer, xmlIO, and xinclude handling.
The listed fixes include an out-of-bounds read, missing overflow checks, an integer-overflow check before invoking a write callback, and a null-check ordering correction before calculating a string length.
No. The available information does not describe attack vectors, required inputs, privileges, affected configurations, or whether default deployments are exposed.
No interim mitigation or workaround is provided in the available release-note excerpt.